पाठ 13 / 28

URLs fetch करने वाले Tools: SSRF और Allow-Lists

Browsing tool को आंतरिक systems तक पहुँचने से रोकें।

Server हमलावर की ओर से fetch करता है

"यह URL fetch करो" tool आपके server पर, आपके network के भीतर चलता है। मॉडल (या injected निर्देश) कोई भी URL चुन सके, तो हमलावर आपके server से आंतरिक सेवाओं (http://localhost, 169.254.169.254 जैसे cloud metadata endpoint, admin panel) को अनुरोध करवाकर उत्तर पढ़ सकता है: server-side request forgery (SSRF)। बचाव: tool जिन hosts से संपर्क कर सके उनकी allow-list; https अनिवार्य; URL ठीक से parse करें और असली hostname की तुलना करें (substring नहीं: docs.example.com@evil.test और docs.example.com.evil.test जाल हैं); DNS resolution के बाद निजी और link-local IP सीमाएँ रोकें, और redirects दोबारा जाँचें; ports, response आकार और समय सीमित करें; और fetcher को आंतरिक सेवाओं या credentials तक पहुँच रहित अलग network खंड में चलाएँ।

चालों से बचने वाली URL allow-list, चलाकर

मैंने यह सादे Python 3 (सिर्फ़ standard library) से चलाया। यहाँ सारे हमले स्थानीय डेटा पर हानिरहित प्रदर्शन हैं, कोई असली system उपयोग नहीं हुआ। सिर्फ़ अनुमत host का सादा https URL पास होता है। सादा http, मिलता-जुलता subdomain, user@host चाल, cloud metadata पता और non-standard port सब अस्वीकृत हैं। असली बचाव resolved IP पते और redirects भी जाँचता है।

from urllib.parse import urlparse

ALLOWED_HOSTS = {"docs.example.com", "api.example.com"}

def allowed(url):
    u = urlparse(url)
    return u.scheme == "https" and u.hostname in ALLOWED_HOSTS and u.username is None and u.port in (None, 443)

for url in ["https://docs.example.com/page", "http://docs.example.com/page", "https://docs.example.com.evil.test/x",
            "https://docs.example.com@evil.test/x", "https://169.254.169.254/latest/meta-data", "https://docs.example.com:8443/x"]:
    print(f"{allowed(url)!s:5} {url}")

Output:

True  https://docs.example.com/page
False http://docs.example.com/page
False https://docs.example.com.evil.test/x
False https://docs.example.com@evil.test/x
False https://169.254.169.254/latest/meta-data
False https://docs.example.com:8443/x

Redirects के बाद दोबारा जाँचें

अनुमत host आंतरिक पते पर redirect कर सकता है। हर hop validate करें।

त्वरित जाँच: URL में अनुमत domain "शामिल" है यह जाँचने की जगह parse किया hostname क्यों तुलना करें?

  • Substring जाँचें धीमी हैं
  • docs.example.com.evil.test जैसी चालें अनुमत नाम रखती हैं पर कहीं और जाती हैं
  • Hostnames सिर्फ़ case-insensitive हैं
  • कोई अंतर नहीं
Answer

docs.example.com.evil.test जैसी चालें अनुमत नाम रखती हैं पर कहीं और जाती हैं — पहले parse करें, फिर असली host की सटीक तुलना करें।